Impact
A remote attacker can exploit a SQL injection flaw in the login1.php page of itsourcecode Online Admission System Project 1.0 by supplying a specially crafted User parameter. The vulnerability arises from inadequate validation of this input, allowing arbitrary SQL statements to be executed against the backend database. If the injection succeeds, an attacker could bypass authentication, retrieve or modify user credentials and other sensitive data, and potentially gain further access to the application. The weakness is associated with CWE‑74 and CWE‑89 and represents a standard SQL injection scenario with potential confidentiality, integrity, and availability impact for the affected system.
Affected Systems
The affected product is itsourcecode's Online Admission System Project version 1.0. The flaw resides in the /admin/login1.php file, and the issue is tied to the user parameter that is passed into SQL queries without proper sanitization. Organizations running this version should assume the application is vulnerable until a patch or remediation is applied. No other versions are explicitly documented as affected in the available information.
Risk and Exploitability
The CVSS score of 6.9 indicates a high level of risk under the base metric set, while the EPSS score is not available and the vulnerability is not listed in the CISA KEV catalog. Because the attack can be initiated remotely over an HTTP interface, the probability of exploitation could be significant if the application is exposed to the internet and no additional mitigations are in place. Given that a public exploit is already documented, administrators should treat this as a medium to high priority risk and act promptly to secure the system.
OpenCVE Enrichment